CVE-2026-89737 is a vulnerability in Linux Kernel
Published on September 11, 2026
usb: typec: thunderbolt: Disable work before freeing tbt on remove
In the Linux kernel, the following vulnerability has been resolved:
usb: typec: thunderbolt: Disable work before freeing tbt on remove
tbt_altmode_remove() drops the plug and cable references without
draining tbt->work. The work function dereferences those references,
and can also requeue itself in its error path. The VDM callbacks can
queue the same work item.
Disable and drain tbt->work before dropping the references. This waits
for an existing invocation and prevents subsequent schedule_work()
calls from queueing it during teardown.
This issue was found by an in-house static analysis tool and confirmed
by manual code review.
Products Associated with CVE-2026-89737
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 100e257386595b3f1865ca8a991e2ba74f9701ff and below ebb840d982a612261cfc8a7687735a140c6c7024 is affected.
- Version 100e257386595b3f1865ca8a991e2ba74f9701ff and below 0a25484fe22f621e151367a59a82330a22ac80bc is affected.
- Version 100e257386595b3f1865ca8a991e2ba74f9701ff and below 92090f6ff2acc81e9dd99881dcfb4f8c1bdaabd3 is affected.
- Version 6.14 is affected.
- Before 6.14 is unaffected.
- Version 6.18.50, <= 6.18.* is unaffected.
- Version 7.2.4, <= 7.2.* is unaffected.
- Version 7.3-rc1, <= * is unaffected.